CVE-2012-0928 describes a critical vulnerability in the ATRAC codec within RealNetworks RealPlayer 11.x, 14.x, RealPlayer SP, and Mac RealPlayer 12.x. This flaw allows remote attackers to execute arbitrary code by tricking a user into opening a specially crafted ATRAC audio file due to improper sample decoding. With a CVSS score of 9.3, this vulnerability is highly severe, requiring medium attack complexity but granting complete confidentiality, integrity, and availability compromise. While no public exploit code (Metasploit, Nuclei, ExploitDB) is readily available and there's minimal community discussion or media coverage, the potential for remote code execution makes it a significant risk.
| Vendor | Product | Version(s) | CPE |
|---|---|---|---|
14.0.0CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:14.0.0:*:*:*:*:*:*:* | ||
14.0.1CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:14.0.1:*:*:*:*:*:*:* | ||
14.0.1.609CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:14.0.1.609:*:*:*:*:*:*:* | ||
14.0.1.633CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:14.0.1.633:*:*:*:*:*:*:* | ||
14.0.2CPE matchmatch criteria | cpe:2.3:a:realnetworks:realplayer:14.0.2:*:*:*:*:*:*:* |
CVSS version used by this source: 2.0
AV:N/AC:M/Au:N/C:C/I:C/A:C
The average CVE in this peer group has 0.0 Twitter, 0.1 Reddit, 0.1 Bluesky, 0.1 Mastodon, and 0.2 GitHub mentions.
No media coverage found for this CVE.
The average CVE in this peer group has 0.1 InfoSec Media, 0.0 Vendor Blog, and 0.0 Security Researcher mentions.
Remediation records are not available for this CVE.